Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-75918

phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file at content/core/data/trackingDDMMYYYY to extract reset tokens and replay them against the password reset API to take over user accounts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 16.5%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-75918


Contact Us

Shodan ® - All rights reserved